DigitalOceanSAFE
DigitalOcean MCP Server for deploying and managing apps on App Platform
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
⚠️ ARCHIVE NOTICE This repository has been archived. Please use [@digitalocean-labs/mcp-digitalocean](https://github.com/digitalocean-labs/mcp-digitalocean/)
[](https://www.npmjs.com/package/@digitalocean/mcp) [](LICENSE)
This MCP server exposes DigitalOcean App Platform functionality through standardized tools that can be used by any MCP client, including Claude Desktop and Cursor. It enables AI assistants to directly manage your DigitalOcean apps without writing code or memorizing API endpoints.
[](https://cursor.com/install-mcp?name=digitalocean&config=eyJjb21tYW5kIjoibnB4IEBkaWdpdGFsb2NlYW4vbWNwIiwiZW52Ijp7IkRJR0lUQUxPQ0VBTl9BUElfVE9LRU4iOiJZT1VSX0RPX1RPS0VOIn19)
📚 Table of Contents
- 🚀 What Can You Do With It?
- 🧰 Prerequisites
- ⚙️ Setting up your DigitalOcean MCP Server
- Generate Your API Token
- Add the Server to Your MCP Client
- Claude Desktop
- Cursor
- Windsurf Setup
- 💬 Example Prompts
- 🛠 Available Tools
- 🧯 Troubleshooting
- 🤝 Contributing
- 📄 License
🚀 What Can You Do With It?
You can now do things like:
- Deploy a new app from a GitHub repo
- Quickly redeploy an existing app with the latest changes
- See logs, restart components, or delete old environments
- Check available regions and create apps based on what’s supported
- Build and deploy an app from scratch, entirely
bda7a2dab9baOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp --env DIGITALOCEAN_API_TOKEN=${DIGITALOCEAN_API_TOKEN} -- npx -y @digitalocean/[email protected]{
"mcpServers": {
"mcp": {
"command": "npx",
"args": [
"-y",
"@digitalocean/[email protected]"
],
"env": {
"DIGITALOCEAN_API_TOKEN": "${DIGITALOCEAN_API_TOKEN}"
}
}
}
}Exposed tools (30)
22 read · 7 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
cancel_deployment | read | Cancel a deployment by ID |
commit_app_rollback | write | Commit an app rollback. This action permanently applies the rollback and unpins the app to resume new deployments. |
create_app | write | Create a new app by submitting an app specification. For documentation on app specifications ( |
create_database_cluster | write | Create a new database cluster. |
create_deployment | write | Create a new deployment for an app |
delete_app | destructive | Delete an app by ID |
download_logs | read | Give the URL of the logs, download the logs and return them as a string. |
get_app | read | Get an app by ID |
get_database_cluster | read | Get information about a specific database cluster. |
get_database_cluster_certificate | read | Get the certificate for a specific database cluster. |
get_database_options | read | Get a list of all database options available for creating a database cluster. This includes available regions, versions, and sizes for each database engine. |
get_deployment | read | Get a deployment by ID |
get_deployment_logs_url | read | Gets the URL of the logs for a deployment. Before fetching the logs, you need to get the URL of the logs. |
get_instance_size_by_slug | read | Retrieve information about a specific instance size slug for |
list_app_alerts | read | List alerts associated to the app and any components. This includes configuration information about the alerts including emails, slack webhooks, and triggering events or conditions. |
list_app_regions | read | List all regions supported by App Platform. |
list_apps | read | List all apps on your account. Information about the current active deployment as well as any in progress ones will also be included for each app. |
list_database_cluster_databases | read | List all databases for a specific database cluster. |
list_database_cluster_users | read | List all users for a specific database cluster. |
list_database_connection_pools | read | List all connection pools for a specific database cluster. |
list_database_firewall_rules | read | List all firewall (trusted sources) rules for a specific database cluster. |
list_database_topics | read | List all topics for a specific database kafka cluster. |
list_databases_cluster | read | List all database clusters in your account. This includes information about each cluster |
list_deployments | read | List all deployments for an app |
list_instance_sizes | read | List all instance sizes for |
revert_app_rollback | read | Revert an app rollback. This action reverts the active rollback by creating a new deployment from the latest app spec prior to the rollback and unpins the app to resume new deployments. |
update_app | write | Update an existing app by submitting a new app specification. For documentation on app specifications ( |
update_app_alert_destinations | write | Update alert destinations for an app |
update_database_firewall_rules | write | Update the firewall (trusted sources) rules for a specific database cluster. |
validate_app_spec | read | Propose and validate a spec for a new or existing app. The request returns some information about the proposed app, including app cost and upgrade cost. If an existing app ID is specified, the app spec is treated as a proposed update to the existing app. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (4)
delete_app
@modelcontextprotocol/sdk, dotenv, zod, @types/node, js-yaml, typed-openapi, typescript
src/specs/digitalocean-openapi.yaml
Gates applied: no_behavioural_pass, no_license.
bda7a2dab9bafull audit observations/trust-audit/mcp-server/digitalocean__digitalocean-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | bda7a2dab9ba | SAFE | B | 89 | first audit |
Questions
What is the DigitalOcean MCP server?
DigitalOcean MCP Server for deploying and managing apps on App Platform
What tools does DigitalOcean expose?
30 in total: 22 read-only, 7 that write, and 1 that can delete or overwrite (delete_app). Every one is listed on this page with its risk.
Is DigitalOcean safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does DigitalOcean need?
It reads DIGITALOCEAN_API_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does DigitalOcean run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @digitalocean/mcp at 0.0.13.
How current is this page?
The grade is for one exact copy of the source (bda7a2dab9ba), read on 2026-10-07. The repository is watched and re-audited when it changes.